Back

HIGH

libxml2: Stack-based buffer overflow in xmlSnprintfElements of libxml2

Published Feb 18, 2025

Description

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.

Affected products

Remediation

Red Hat statement

This vulnerability is rated as important because it involves a stack-based buffer overflow in the xmlSnprintfElements function within valid.c. Exploiting this issue requires DTD validation to occur on an untrusted document or untrusted DTD, making it a potential security risk for applications using libxml2 that do not adequately restrict DTD input.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 18, 2025
Updated Feb 26, 2026
Reserved Jan 28, 2025
CISA Vulnrichment
Updated Jul 23, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Feb 18, 2025